Stack-based buffer overflow in corosync - CVE-2025-30472

 

Stack-based buffer overflow in corosync - CVE-2025-30472

Published: March 26, 2025


Vulnerability identifier: #VU106058
CSH Severity: Medium
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30472
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a boundary error in orf_token_endian_convert() function in exec/totemsrp.c. A remote attacker can send an overly large UDP packet to the application, trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability requires that encryption is disabled.


Affected software

corosync
SUSE Enterprise Server 15 SP3 Business Critical
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Availability Extension 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Anolis OS
Fedora
openSUSE Leap
openEuler
Ubuntu
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Db2 Big SQL
IBM OpenPages with Watson
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
libcorosync_common4-32bit
libcmap4-32bit-debuginfo
libsam4-32bit
libcpg4-32bit
libvotequorum8-32bit
libquorum5-32bit-debuginfo
libcfg6-32bit-debuginfo
libcpg4-32bit-debuginfo
libsam4-32bit-debuginfo
libvotequorum8-32bit-debuginfo
libtotem_pg5-32bit-debuginfo
libquorum5-32bit
libcfg6-32bit
libtotem_pg5-32bit
libcorosync_common4-32bit-debuginfo
libcmap4-32bit
libvotequorum8-64bit-debuginfo
libcmap4-64bit
libcorosync_common4-64bit-debuginfo
libcmap4-64bit-debuginfo
libsam4-64bit
libcfg6-64bit
libcpg4-64bit
libvotequorum8-64bit
libquorum5-64bit
libsam4-64bit-debuginfo
libtotem_pg5-64bit
libcfg6-64bit-debuginfo
libtotem_pg5-64bit-debuginfo
libcpg4-64bit-debuginfo
libquorum5-debuginfo
libcorosync_common4-64bit
libquorum5-64bit-debuginfo
libcfg6
libcmap4-debuginfo
corosync-testagents-debuginfo
corosync-debugsource
libcorosync-devel
libsam4
libvotequorum8-debuginfo
corosync
corosync-debuginfo
corosync-qdevice-debuginfo
corosync-qnetd-debuginfo
libquorum5
libtotem_pg5
libtotem_pg5-debuginfo
libcorosync_common4
corosync-qdevice
libsam4-debuginfo
libcpg4-debuginfo
libvotequorum8
corosync-testagents
libcfg6-debuginfo
libcorosync_common4-debuginfo
libcpg4
corosync-qnetd
libcmap4
corosync (Ubuntu package)
corosync-vqsim
corosynclib
corosynclib-devel
corosync-epel

How to mitigate CVE-2025-30472

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.1
Db2 Big SQL - update to 8.1
IBM OpenPages with Watson - update to 9.1.2
libcorosync_common4-32bit - update to 2.4.6-150300.12.13.1
libcmap4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-32bit - update to 2.4.6-150300.12.13.1
libcpg4-32bit - update to 2.4.6-150300.12.13.1
libvotequorum8-32bit - update to 2.4.6-150300.12.13.1
libquorum5-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcfg6-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libvotequorum8-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5-32bit - update to 2.4.6-150300.12.13.1
libcfg6-32bit - update to 2.4.6-150300.12.13.1
libtotem_pg5-32bit - update to 2.4.6-150300.12.13.1
libcorosync_common4-32bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-32bit - update to 2.4.6-150300.12.13.1
libvotequorum8-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-64bit - update to 2.4.6-150300.12.13.1
libcorosync_common4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcmap4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libsam4-64bit - update to 2.4.6-150300.12.13.1
libcfg6-64bit - update to 2.4.6-150300.12.13.1
libcpg4-64bit - update to 2.4.6-150300.12.13.1
libvotequorum8-64bit - update to 2.4.6-150300.12.13.1
libquorum5-64bit - update to 2.4.6-150300.12.13.1
libsam4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-64bit - update to 2.4.6-150300.12.13.1
libcfg6-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libtotem_pg5-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4-64bit - update to 2.4.6-150300.12.13.1
libquorum5-64bit-debuginfo - update to 2.4.6-150300.12.13.1
libcfg6 - update to 2.4.6-150300.12.13.1
libcmap4-debuginfo - update to 2.4.6-150300.12.13.1
corosync-testagents-debuginfo - update to 2.4.6-150300.12.13.1
corosync-debugsource - update to 2.4.6-150300.12.13.1
libcorosync-devel - update to 2.4.6-150300.12.13.1
libsam4 - update to 2.4.6-150300.12.13.1
libvotequorum8-debuginfo - update to 2.4.6-150300.12.13.1
corosync - update to 2.4.6-150300.12.13.1
corosync-debuginfo - update to 2.4.6-150300.12.13.1
corosync-qdevice-debuginfo - update to 2.4.6-150300.12.13.1
corosync-qnetd-debuginfo - update to 2.4.6-150300.12.13.1
libquorum5 - update to 2.4.6-150300.12.13.1
libtotem_pg5 - update to 2.4.6-150300.12.13.1
libtotem_pg5-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4 - update to 2.4.6-150300.12.13.1
corosync-qdevice - update to 2.4.6-150300.12.13.1
libsam4-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4-debuginfo - update to 2.4.6-150300.12.13.1
libvotequorum8 - update to 2.4.6-150300.12.13.1
corosync-testagents - update to 2.4.6-150300.12.13.1
libcfg6-debuginfo - update to 2.4.6-150300.12.13.1
libcorosync_common4-debuginfo - update to 2.4.6-150300.12.13.1
libcpg4 - update to 2.4.6-150300.12.13.1
corosync-qnetd - update to 2.4.6-150300.12.13.1
libcmap4 - update to 2.4.6-150300.12.13.1
corosync (Ubuntu package) - addressed in versions 3.0.3-2ubuntu2.2, 3.1.6-1ubuntu1.1, 3.1.7-1ubuntu3.1, 3.1.8-2ubuntu1.1
corosync - update to 3.1.5-2
corosync-debuginfo - update to 3.1.5-2
corosync-debugsource - update to 3.1.5-2
corosync-vqsim - update to 3.1.5-2
corosynclib - update to 3.1.5-2
corosynclib-devel - update to 3.1.5-2
corosync-epel - update to 3.1.9-0.2.el9.1
corosync - update to 3.1.9-2
corosync-vqsim - update to 3.1.9-2
corosynclib - update to 3.1.9-2
corosynclib-devel - update to 3.1.9-2
corosync - addressed in versions 3.1.9-2.fc40, 3.1.9-2.fc41, 3.1.9-3.fc42

External References

Related Security Bulletins